OS Credential Dumping: DCSync

Threat Actors may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.

ID: ATAGS-T1121.003
Sub-technique of:  ATAGS-T1121
Targeted Components: Mission, Personnel & Identity
Responsibility: Shared
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.